<?php

include ('../session.php');
include ('../db.php');
include ('../functions.php');
include ('config.php');

if ($action == 'add')
{
  print_r ($_POST);

  $c_name = mysql_clean ($name);
  $c_value = floatval ($value);

  $query = "select item_id
            from " . DKP_ITEMS . "
            where item_name = '$c_name'";
  $result = mysql_query ($query);

  $row = mysql_fetch_array ($result);

  if ($row)
  {
  }

  $query = "select idvalue
            from ids
            where idid = " . ID_ITEM;
  $result = mysql_query ($query);

  $row = mysql_fetch_array ($result);

  $itemid = $row['idvalue'];
  $c_itemid = intval ($itemid);

  $query = "insert into " . DKP_ITEMS . "
            (item_id, item_name, item_value)
            values ($c_itemid, '$c_name', $c_value)";
  $result = mysql_query ($query);

  $query = "update ids
            set idvalue = " . intval ($itemid + 1) . "
            where idid = " . ID_ITEM;
  $result = mysql_query ($query);
}
else if ($action == 'update')
{
}
else if ($action == 'remove')
{
}

$output = '';

$output .= "
<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN\">
<html>
  <head>
    <title>Panic Points - Add Item</title>
    <link href=\"../general.css\" rel=\"stylesheet\" type=\"text/css\">
  </head>
  <body>";

include ('navigation.php');

$output .= "
    <form name=\"itemform\" id=\"itemform\" action=\"additem.php\" method=\"POST\">
      <input type=\"hidden\" name=\"action\" id=\"action\" value=\"\">
      <table>
        <tr>
          <td>name</td>
          <td><input type=\"edit\" name=\"name\"></td>
        </tr>
        <tr>
          <td>default value</td>
          <td><input type=\"edit\" name=\"value\"></td>
        </tr>
        <tr>
          <td colspan=\"2\">
            <button onclick=\"document.getElementById ('action').value = 'add'; document.getElementById ('itemform').submit ()\">add</button>&nbsp;
            <button onclick=\"document.getElementById ('action').value = 'update'; document.getElementById ('itemform').submit ()\">update</button>&nbsp;
            <button onclick=\"document.getElementById ('action').value = 'remove'; document.getElementById ('itemform').submit ()\">remove</button>
          </td>
        </tr>
      </table>
    </form>";

$output .= "
  </body>
</html>";

echo $output;
